Overview
This guide explains how to create an Identity Provider (IDP) Certificate in Salesforce and configure it within a SAML-enabled Connected App, which is required for Single Sign-on (SSO) access to the GovSearchAI platform.
Audience
Salesforce Administrators
IT Support
Create IDP Certificate
Click the gear icon and select Setup.

Go to Certificate and Key Management using Setup search and click Create Self-Signed Certificate.

Enter a Label and Unique Name and click Save.

Self-Signed IDP Certificate is created.
Go to Identity Provider using Setup search and click Edit.

Select your previously created Self-Signed IDP Certificate and click Save.

A confirmation message displays.
Click OK.

Go to Manage Connected Apps using Setup search and scroll down to open SF IDP for Cognito.

Click Edit Policies.

Scroll down to select Idp Certificate as your previously created Self-Signed IDP Certificate and click Save.

Delete Expired IDP Certificate
Post completing all the above mentioned steps, log out from your Salesforce instance, re-login, clear your browser cache, and verify that all GovSearchAI features are working correctly.
Post verifying that all GovSearchAI features are working correctly, ensure that you delete the older expired Self-Signed IDP Certificate.
Go back to Certificate and Key Management using Setup search and click Del against your expired Self-Signed IDP Certificate.

A confirmation message displays.
Click OK.

Expired Self-Signed IDP Certificate is deleted.
Note that in some scenarios during deletion, if SAML SSO is already enabled on your instance, then an error message may display. To resolve this, perform the following steps:
Go to Single Sign-on Settings using Setup search and click Edit.
Ensure that Request Signing Certificate is selected as your previously created Self-Signed IDP Certificate and click Save.
